Last Updated: June 29, 2023
If you are a parent or guardian of a child, please review the section titled Children’s Information below.
- Additional Disclosures for California Residents
- Additional Disclosures for Nevada Residents
- Additional Disclosures for Virginia Residents
- Additional Disclosures for Colorado Residents
- Additional Disclosures for Connecticut Residents
- Additional Disclosures for Data Subjects in the European Economic Area, Switzerland, and United Kingdom
If you have any questions or wish to exercise your rights and choices, please contact us as set out in the “Contact Us” section below.
2. ESRB PRIVACY CERTIFIED
3. INFORMATION COLLECTION
A. Information You Provide
Wizards collects information you provide directly via the Service. The data we collect may include data (whether alone or in combination) that identifies you personally. The categories of information we have collected in the last 12 months include the following:
- Contact Data. We collect your first and last name, email address, postal address, telephone number and other similar contact data.
- Credentials. We collect passwords, password hints and similar security information used for authentication and account access.
- Demographic Data. We collect demographic information such as about your age, birth date, gender and country.
- Payment Data. We collect data necessary to process your payment if you make purchases, such as your payment instrument, shipping address and transaction numbers.
- Profile Data. We collect your username, interests, favorites, gamer data and other profile information.
- Contacts. We collect data about your contacts if you choose to match with your contacts on the Service or invite your contacts to join the Service.
- Content. We collect the content of messages you send to us, such as feedback and product reviews you write, or questions and information you provide for customer support. We also collect the content of your communications as necessary to provide you with the services you use. For example, if you chat with another user through the Service, we need to collect the content of that chat to display it to you and the other user as you direct.
Wizards collects data from you at various points while you are using the Service, including as described below:
- Account Registration. To register an account with Wizards, you must, at a minimum, provide your date of birth, location, email, a username and password. To participate in other Wizards offerings, such as organized play, you may be required to provide your first name and last name, city, country, postal code, gender, email address, password, username and screen name.
- Profile. For certain parts of our Service, your personal profile (“Your Profile”) will be automatically populated with the screen name you provided at registration. Where applicable, the information in Your Profile, including any information or content you voluntarily add to Your Profile will be made public by default. To change Your Profile privacy settings for your Wizards account, log in to myaccounts.wizards.com and go to your My Account tab, then click “Edit Public Profile & Settings.” In this section, you may also change Your Profile information, who can view your page and activity, and who can contact you on these parts of the Service, as well as control how we communicate with you. Your Profile for these parts of the Service will be searchable by screen name, and you can change the visibility of Your Profile by de-selecting the “Profile is visible to other users” and “Profile is searchable” boxes in Privacy Settings. To change Your Profile privacy settings for your D&D Beyond account, log in to dndbeyond.com and sign in to your account, hover on your screen name in the top right, and select “Profile.” On the Profile page, click the “Edit Profile” button. From here, you may edit the information that appears on your profile page, including your avatar photo. Please note: The photo you selected (you are not required to upload a personal photo) as your avatar and your screen name for these parts of the Service will always display on your page, posts, and in search results. You are responsible for any information and content you choose to make public either through Your Profile, or by posting on the Service. Profile settings and data processing may differ based on the part of the Service you are using.
- Message Boards, Forums, Blogs, and Chats. Wizards provides message boards, blogs, chats, and other public forums on the Service for exchanging information and communicating with other users. Please note that any information, user content, or any other materials that you post on our Service, including any information from Your Profile, where applicable, that you choose to make public, may be available for any user of the Service to read, and are therefore no longer private and may be disclosed by third parties. If you post information, materials, or other content on the Service, you are providing information that can be collected and used by others that you do not know, for their own purposes, including the distribution of unsolicited communications.
- Online Stores. Visitors purchasing goods and services through our Service will need to provide valid Payment Data, in addition to Contact Data such as name, mailing address, phone number and email address.
- Promotions. To participate in some of our sweepstakes, contests, surveys, or other promotions (“Promotions”), you may be asked to provide an email address or screen name, so that we can let you know if you won a prize. We may also request your name and home address in order to send you products or information by regular mail.
- Customer Service. When you contact customer service you may be asked to provide us with information such as your name, telephone number, address and email. We collect this information as part of our customer service efforts and it is used to confirm your identity, respond to your inquiry or comments, for training purposes, and to assist us in providing better products and services.
- Wizards Play Network. Participants, including store owners and event organizers, have the opportunity to sign up with the Wizards Play Network in order to run organized play events. You must provide certain information to be eligible to participate in organized play.
- Job Postings. Our Service allows for the online submission of resumes, employment and education history, transcript, writing samples, and references which are used solely for the purpose of accepting and evaluating candidate submissions for job postings.
- Online Surveys. In order to improve the user experience at our Service, we may employ online surveys that request for visitors to volunteer information about themselves and provide us feedback about why they visit our Service and suggestions for improvement.
Whatever the activity may be, we will only collect information to the extent it is reasonably necessary to fulfill your requests and our legitimate business objectives. If you do not want to submit certain information when requested, you may not be able to access certain areas on our Service or take advantage of certain features of our Service. You may choose to voluntarily submit other information to us through the Service that we do not request, and, in such instances, you are solely responsible for such information.
B. Information Collected Automatically
We automatically collect information when you use our Service. The categories of information we have automatically collected in the last 12 months include the following:
- Service Use Data. We collect data about the features you use, the products or services you view and purchase, the time of day you browse, information regarding your interaction with the Service, and the web pages you visit.
- Game-Related Data. We collect data about your use of games made available through the Service (“Game-Related Data”). Game-Related Data includes information about your game preferences, participation, performance and achievements in the game, your frequency of play, etc.
- Device, Connectivity, and Configuration Data. We collect data about the type of device or browser you use, your device’s operating software, your regional and language settings, and other similar information. This also includes IP address, MAC address, mobile Ad Ids (e.g., IDFA or AAID), and other device identifiers.
- Location Data. We collect data about your location, which can be precise or imprecise. Precise location data can be Global Navigation Satellite System (GNSS) data (e.g., GPS), as well as data identifying nearby cell towers and Wi-Fi hotspots. We collect precise location data when you enable location-based products or features. Imprecise location data includes, for example, a location derived from your IP address or data that indicates where you are located with less precision, such as at a city or postal code level.
We use various current – and later – developed technologies to collect this data (“Tracking Technologies”), including the following:
- Log Files. Log files are files that record website activity and gather statistics about web users' browsing habits. These entries help Wizards determine (among other things) how many and how often users have visited our Service, which pages they've visited, and other similar data. We also use log file entries for our internal marketing and demographic studies, so we can constantly improve the online services we provide you.
- Clear GIFs. Clear GIFs, sometimes called “pixel tags,” or “web beacons” are file objects, usually a graphic image such as a transparent one pixel-by-one-pixel GIF, that are placed on a web page, advertisement, or in an email message. The GIF may tell us the IP address of the device that fetched our page, the URL of the page the GIF is on, the time the page was viewed, the type of browser used, and it can also identify a previously set cookie value, and how and where a user accessed a website. We may use this information to count visitors across our Service and understand how they navigate and use our Service.
- Location-Identifying Technologies. GPS, WiFi, Bluetooth, and other location-aware technologies may be used to determine your device’s location, sometimes precisely. Location data may be used for purposes such as verifying your device’s location and delivering or restricting relevant content and advertising based on that location.
- App-Specific Technologies. Our apps include app-specific technologies, such as SDKs and APIs provided by third parties. An SDK is code embedded in an app that sends information about your use to a server and is in effect the app version of a GIF. The information collected through such technologies often includes your mobile Ad Id.
For further information on how we use Tracking Technologies and your rights and choices regarding them, please see the sections titled Social Media and Technology Integrations and Your Rights and Choices.
C. Information from Other Sources
We also obtain information about you from third party sources. The categories of third-party sources from which we have collected information in the last 12 months include the following:
- Data brokers or resellers from which we purchase Demographic Data to supplement the data we collect.
- Social networks or gaming platforms (such as Steam or Twitch) when you grant us permission to access data such as Contact Data, Demographic, Data, Profile Data, Contacts and Content.
- Partners with which we offer co-branded services, sell or distribute our products, or engage in joint marketing activities provide us Contact Data, Demographic Data, Profile Data, Contacts and Content.
For further information on these sources, see the section titled Social Media and Technology Integrations below.
4. INFORMATION USE
|Possible Use||Possible Information|
|To operate, manage, and provide you with our Service.||Contact Data, Credentials, Demographic Data, Profile Data, Contacts, Content, Information Collected Automatically|
|To perform services requested by you, such as to respond to your comments, questions, and requests, and provide customer service.||Contact Data, Information Collected Automatically|
|To send you technical notices, updates, security alerts, information regarding changes to our policies, and support and administrative messages.||Contact Data, Information Collected Automatically|
|To prevent and address fraud, breach of policies or terms, and threats or harm.||Contact Data, Credentials, Profile Data, Information Collected Automatically|
|To monitor and analyze trends, usage, and activities.||Contact Data, Demographic Data, Profile Data, Contacts, Information Collected Automatically|
|To fulfill product orders.||Contact Data, Payment Data, Information Collected Automatically|
|For our internal research and demographic studies, so we can constantly improve the Service or other Wizards websites, applications, marketing efforts, products and services.||Contact Data, Demographic Data, Profile Data, Contacts, Information Collected Automatically|
|To send you direct marketing communications including information about new products, contests, features and enhancements, special offers and other events of interest.||Contact Data, Information Collected Automatically|
|To provide you with advertisements on our Service and other services tailored to your interests.||Contact Data, Profile Data, Contacts, Information Collected Automatically|
|To verify your eligibility and deliver prizes in connection with Promotions you have entered.||Contact Data, Profile Data, Contacts, Content, Information Collected Automatically|
|To fulfill any other business or commercial purposes disclosed to you, at your direction, or with your consent.||Contact Data, Credentials, Demographic Data, Profile Data, Contacts, Content, Information Collected Automatically|
Notwithstanding the above, we may use publicly available information (as that term is defined by applicable law) or information that does not identify you (including information that has been de-identified or aggregated, as those terms are defined by applicable law) for any purpose to the extent permitted by applicable law. For information on your rights and choices regarding how we use information about you, please see the section titled Your Rights and Choices below.
5. DISCLOSURE OF INFORMATION
A. Information Disclosed in the Last 12 Months
- Service Providers. Wizards discloses information about you to entities that process the information on our behalf (“Service Providers”). Service Providers assist us with operating our Service and provide us with other services such as organized play, community operations, online product fulfillment, prize payments, email services, marketing and promotional services, data analytics, and technical support. Also, if you make a purchase on the Service, your Payment Data may be processed by a payment processing Service Provider as necessary to complete your purchase (for example, to process your credit card). To the extent required by law, these Service Providers are contractually prohibited from using your information about you for any purpose other than to provide this assistance, and they agree to maintain the confidentiality, security and integrity of information they receive from us. We may, however, permit Service Providers to use aggregate information that does not identify you or de-identified information for any purposes except as prohibited by applicable law. We disclose the following categories of information to Service Providers: Contact Data, Payment Data, Credentials, Demographic Data, Profile Data, Contacts, and Content.
- Vendors. We disclose information to vendors, including analytics and advertising technology companies. Vendors may act as our Service Providers, or in certain contexts, independently decide how to process your information. For more information on advertising and analytics, see the section titled Analytics and Advertising below. For Vendors, we disclose the following categories of information to vendors: Contact Data, Credentials, and Profile Data.
- Affiliates. Wizards discloses information to its related entities including its parent and sister companies. For example, we may disclose your information to our affiliates for customer support, marketing, or technical operations. Such information includes: Contact Data, Credentials, Payment Data, and Profile Data.
- Partners. We disclose information to our partners in connection with offering you co-branded services, selling or distributing our products, tournament and organized play activities, or engaging in joint marketing activities. For example, we may disclose information about you to a retailer for purposes of providing you with product support including Contact Data, Credentials, and Profile Data.
- Tournament and Organized Play. If you engage in organized play, your full name, DCI number, city, state, nationality, username and email will be accessible by authorized tournament organizers, retail locations that are part of the Wizards Play Network, members of the Wizards’ community that are adjudicating organized play events, and prize fulfillment Service Providers. These parties are independent of Wizards, and, to the extent required by law, they are contractually prohibited from using your information for any other purpose than that for which it was provided to them, and they agree to maintain the confidentiality, security and integrity of information they receive from us. Your information may also be disclosed to members of the Wizards’ community who are engaged in investigating violations of tournament rules and the Code of Conduct. Additionally, your full name, city, and country may appear in online leaderboards and organized play event results. Video Data may also be available to tournament organizers and retail locations that are part of the Wizards Play Network if you participate in organized play activities through SpellTable.
- Promotions. Our Promotions may be jointly sponsored or offered by other entities. If you voluntarily choose to enter a Promotion, we disclose information as set out in the official rules that govern the Promotion as well as for administrative purposes and as required by law (e.g., on a winners list). By entering, you agree to the official rules that govern that Promotion, and may, except where prohibited by applicable law, allow the sponsor and/or other parties to use your name, voice and/or likeness in advertising or marketing materials. We disclose the following information categories to promotional partners: Contact Data, Profile Data, and Content.
- Facilitating Requests. We disclose information at your request or direction, such as when you choose to disclose information to a social network about your activities on the Service or link your Wizards account to gaming platforms (such as Steam or Twitch). Such disclosures include: Contact Data, Credentials, Profile Data, Contacts, and Content.
B. Information Disclosed General
In addition to the categories listed above, Wizards may disclose information about you as follows:
- Merger or Acquisition. In the event of, or during negotiations of, an actual or proposed merger, acquisition, reorganization, bankruptcy, or other similar event, your information, including personal data, may be disclosed to Wizards' successors or assigns or other third parties involved in the event. In the event of a merger or acquisition, we may disclose the following categories of information: Contact Data, Credentials, Demographic Data, Payment Data, Profile Data, Contacts, and Content.
- Security and Compelled Disclosure. We may disclose your information, including personal data, to comply with law or other legal process, and where required, in response to requests by public authorities, including to meet national security or law enforcement requests. We may also disclose your information in connection with an investigation of fraud, harassment, intellectual property infringements, or other activity that is illegal, a violation of our policies, or may expose you or us to legal liability. We may also disclose your information to protect the rights, property, life, health, security and safety of us, the Service or any third party. Such disclosures may include Contact Data, Payment Data, Credentials, Demographic Data, Profile Data, Contacts and Content.
- Consent. We may disclose your information for any other business or commercial purpose with notice to you and with your consent.
Without limiting the foregoing, in our sole discretion, we may disclose aggregated information which does not identify you or de-identified information about you with third parties or affiliates for any purpose except as prohibited by applicable law. For information on your rights and choices regarding how we disclose your information, please see the section titled Your Rights and Choices below.
6. CHILDREN’S INFORMATION
A. A Note to Parents
If your Child is a California resident, review the section titled Additional Disclosures for California Residents. If your child is in Colorado or Connecticut, see the sections titled Additional Disclosures for Colorado Residents and Additional Disclosures for Connecticut Residents below. If your child is in the European Economic Area, Switzerland, or United Kingdom, review the section titled Additional Disclosures for Data Subjects in the European Economic Area, Switzerland, and the United Kingdom.
B. Services Directed to Children
Wizards may also offer certain areas of the Service that are identified as for Children and on such special areas of our Service we will either provide direct notice to a parent of our collection and use of Children’s personal information as defined by COPPA and obtain prior verifiable parental consent or limit our data collection activities to comply with the obligations of COPPA for Child-directed services. For a list of services that Wizards treats as being directed to Children under COPPA, please contact us as set forth in the section titled Contact Us.
C. Collection, Use, and Sharing of Children's Information
Wizards may collect, use, and disclose personal information from Children if it is submitted by a Child with prior verifiable parental consent or by the parent or guardian of the Child. To determine who is younger than 13 years old and whether prior verifiable parental consent is required, we ask all users who wish to register to submit their date of birth. Those users that indicate they are Children are either blocked from the activity or taken through a parental consent process. As part of the parental consent process, parents have the choice of consenting to our collection and internal use of their Child’s personal information but prohibiting us from disclosing that information to third parties (except to the extent such disclosure is integral to our Service). If we learn or have reason to suspect that we have collected information from a Child in violation of COPPA, we will promptly delete it.
In limited circumstances, in accordance with COPPA, Wizards does not require verifiable parental consent prior to collection, use, or sharing of Children’s personal information. For example, Wizards may collect and store persistent identifiers (e.g., cookies, IP addresses, etc.) from Children without prior verifiable parental consent where we collect no other Children’s personal information and such persistent identifiers are collected solely for the purpose of providing support for the internal operations of the Service.
Please refer to the sections titled Information Collection, Information Use, and Disclosure of Information for further details on how we process information.
D. Parental Access
A parent or guardian who has already given Wizards permission to collect, use, and disclose their Child’s personal information can, at any time, do the following: (1) review, correct, or delete the Child’s personal information; and/or (2) discontinue further collection, use, or disclosure of the Child’s personal information. To do so, please refer to the confirmation email provided to you when you gave consent or contact us as set forth in the section titled Contact Us below. Please be sure to include your Child’s name and email address, your name and email address, and the area of the Service on which your Child is registered.
7. SOCIAL MEDIA AND TECHNOLOGY INTEGRATIONS
We offer parts of our Service through websites, locations, platforms, and services operated, owned, or controlled by separate entities. In addition, we integrate technologies operated, owned, or controlled by separate entities into parts of our Service. Some examples include:
- Links. Our Service includes links to websites, platforms, and other services not operated or controlled by us.
Please note that when you interact with other entities, including when you leave our Service, those entities may independently collect information about you. The information collected and stored by those entities remains subject to their own policies and practices, including what information they disclose to us, your choices on their services and devices, and whether they store information in the U.S. or elsewhere. We encourage our users to read third party privacy policies before submitting any information to such third parties.
For further information on Tracking Technologies and your rights and choices regarding them, please see the sections titled Information Collected Automatically and Your Rights and Choices below.
8. ANALYTICS AND ADVERTISING
We use analytics providers, such as Google Analytics, to help us analyze your use of the Service, compile statistic reports on the Service’s activity, and provide other services relating to Service activity and internet usage. We also work with agencies, advertisers, ad networks, and other technology services to place ads for our products and services on other websites and services. As part of this process, we may incorporate Tracking Technologies into our own Service (including our website and emails) as well as into ads displayed on other websites and services. Some of these Tracking Technologies may track your activities across time and services for purposes of associating the different devices you use and delivering relevant ads and/or other content to you on the Service and other services after you have left the Service (“Interest-based Advertising”).
We also use audience matching services to reach people (or people with similar activity patterns to those people) who have visited our Service or are identified in one or more of our databases (“Matched Ads”). This is done by us uploading a customer list to a technology service or incorporating a pixel from a technology service into our own Service, and the technology service matching common factors between our data and their data. For instance, we incorporate the Facebook pixel on our Service and may disclose your email address to Facebook as part of our use of Facebook Custom Audiences. Some technology services, such as LiveRamp, may provide us with their own data, which is then uploaded into another technology service for matching common factors between those factors.
For further information on the types of Tracking Technologies we use on the Service and your rights and choices regarding analytics, Interest-based Advertising, and Matched Ads, please see the Information Collected Automatically and Your Rights and Choices sections.
9. YOUR RIGHTS AND CHOICES
A. Jurisdictional Rights
B. Review and Updating Account Information
If you have registered an account, you may at any time review or update the Contact Data in your account through your account settings or by contacting us as set forth in the section titled Contact Us below. Please be sure to include in your message the name of the feature for which you registered and the email address you used to register so that we can verify your request. We may require additional information from you to allow us to confirm your identity. Please note that we will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
C. Posted Content
If you wish to review, correct, or delete content or information you have publicly posted on our Service you may do so by visiting the individual post and selecting the “Edit” or “Delete” options. Alternatively, you may contact us as set forth in the section titled Contact Us below with your request. Requests must state that the user personally posted such content or information and detail where the content or information is posted. Note that we will make reasonable good-faith efforts to remove the post from prospective public view, and removal of this content or information from public view does not guarantee complete or comprehensive removal. After your removal request has been honored, we may retain copies of the content or information you have previously posted on our servers. Additionally, we are not required to remove your posted content or information if we are required by law to retain it.
D. Tracking Technology Choices
- Cookies and GIFs. Most browsers accept cookies by default. You can instruct your browser, by changing its settings, to decline or delete cookies. If you use multiple browsers on your device, you will need to instruct each browser separately. Your ability to limit cookies is subject to your browser settings and limitations.
- App-Specific Technologies. You can reset your mobile Ad ID at any time through your device settings, which will allow you to limit the use of information collected about you. For information on how to do this on Apple devices, visit Apple.com or https://support.apple.com/en-us/HT202074. For information on how to do this on Android devices, visit Google.com. You can stop all collection of information via an app by uninstalling the app.
- Location-Identifying Technologies. The location data collected through an app depends on your device settings and app permissions. You can exercise choice over the location data collected through our apps by (i) for GPS data, disabling location in your device settings or disabling location permissions to that app; (ii) for Bluetooth data, disabling Bluetooth and any Bluetooth scanning option in your device settings; or (iii) for WiFi data, disabling WiFi and any WiFi scanning option in your device settings. You can stop collection of all location data via an app by uninstalling the app.
- Do Not Track. Your browser settings may allow you to automatically transmit a “Do Not Track” signal to online services you visit. Note, however, there is no industry consensus as to what site and app operators should do with regard to these signals. Accordingly, we do not monitor or take action with respect to “Do Not Track” signals.
Please be aware that if you disable or remove Tracking Technologies some parts of the Service may not function correctly.
E. Analytics and Interest-Based Advertising
Some of the third parties that collect information from or about you on the Service in order to provide more relevant advertising to you participate in the Digital Advertising Alliance (“DAA”) Self-Regulatory Program for Online Behavioral Advertising. This program offers a centralized location where users can make choices about the use of their information for online behavioral advertising. To learn more about the DAA and your opt-out options for their members, please visit (i) for website opt-out, http://www.aboutads.info/choices; and (ii) for mobile app opt-out, http://www.aboutads.info/appchoices. In addition, some of these third parties may be members of the Network Advertising Initiative ("NAI"). To learn more about the NAI and your opt-out options for their members, please visit http://www.networkadvertising.org/choices/. Opting-out only means that the selected members should no longer deliver certain Interest-based Advertising to you; it does not mean you will no longer receive any targeted content and/or ads (e.g., from other ad networks).
To opt-out of us using your data for Matched Ads, please contact us as set forth in the Contact Us section below and specify that you wish to opt-out of Matched Ads. We will request that the applicable technology service not serve you Matched Ads based on information we provide to it. Alternatively, you may directly contact the applicable technology service to opt-out.
You may also limit our use of information collected from or about your mobile device for purposes of serving targeted ads to you by going to your device settings and selecting "Limit Ad Tracking" (for iOS devices) or "Opt-out of Interest-Based Ads" (for Android devices).
Please note that if you opt-out using any of these methods, the opt-out will only apply to the specific browser or device from which you opt-out. We are not responsible for the effectiveness of, or compliance with, any third-party opt-out options or programs, or the accuracy of any company statements regarding their opt-out options or programs.
F. Unlinking Your Accounts
If you have linked your Wizards account with certain social network or gaming platforms, such as Facebook or Steam, you may unlink your accounts at any time by visiting your Wizards account settings. Please note that unlinking your accounts will not affect any information previously disclosed through the linking. Wizards is not responsible for any platform practices, and we recommend that you carefully review their online policies.
10. DATA SECURITY
Wizards takes reasonable steps to help protect the security and integrity of any information you provide to us by implementing and maintaining administrative, physical, and technical safeguards. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of your information collected through our Service.
11. INTERNATIONAL TRANSFER OF INFORMATION
Wizards is based in the U.S. and the information it collects is governed by U.S. law. If you are accessing the Service from outside the U.S., please be aware that information collected through the Service may be transferred across borders, and from your country or jurisdiction to other countries or jurisdictions around the world, including the U.S. Note that data protection laws in the U.S. and other jurisdictions may be different from those of your country of residence. By using the Service, you are expressly consenting to the transfer to and from, processing, usage, sharing, and storage of your information, including personal data, in the U.S. as well as other jurisdictions where Wizards conducts business or provides services. If your data is collected in the United Kingdom, the European Economic Area or Switzerland, we will transfer your personal data subject to appropriate safeguards, such as Standard Contractual Clauses.
13. CONTACT US
Wizards of the Coast
ATTN: Customer Support
P.O. Box 707
Renton, WA 98057-0707
US/Canada: (800) 324-6496
Other countries: (425) 204-8069
Note: We are available Monday through Friday, from 9:00 am to 6:00 pm Pacific Time, and also on weekends from 10:00 am to 4:00 pm Pacific Time.
Submit a help request at https://support.wizards.com
For Europe-specific requests, you can reach our DPO at: email@example.com
14. ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS
California provides additional rights to California residents, including through the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CPRA”). This section addresses those rights and only applies to California residents.
A. Notice of Collection
We have collected the following categories of personal information (as described in the CCPA) in the past 12 months:
- Identifiers, including name, postal address, email address, and online identifiers (such as IP address);
- Customer records, including phone number, billing address, and credit or debit card information;
- Characteristics of protected classifications under California or federal law, including gender;
- Commercial or transactions information, including records of products or services purchased, obtained, or considered;
- Internet activity, including browsing history, search history, and interactions with a website, email, application, or advertisement;
- Non-precise geolocation data, including location derived from an IP address.
- Professional, employment, or education-related information; and
- Inferences drawn from any of the information identified in this section.
For further details on the personal information we collect and the sources from which we obtain such personal information, please see the section above titled Information Collection.
Wizards collects and uses this personal information set out above for the business and commercial purposes described in the section above titled Information Use. We disclose this personal information to the categories of persons set out in the above section titled Disclosure of Information. Please visit those sections for further details.
We do not sell your personal information as that term is traditionally understood. However, some of our disclosures of personal information may be considered a “sale” or “share” as those terms are defined under the CCPA. A “sale” is broadly defined under the CCPA to include a disclosure for something of value, and a “share” is broadly defined under the CCPA to include a disclosure for cross-context behavioral advertising. We collect, sell, or share the following categories of personal information for commercial purposes: identifiers, characteristics, commercial or transactions information, internet activity, non-precise geolocation data, and inferences drawn. The categories of third parties to whom we sell or share your personal information include, where applicable, vendors and other parties involved in cross-context behavioral advertising. For details about your rights regarding sales and shares, please see the below section titled Do Not Sell or Share My Personal Information.
B. Sensitive Personal Information
In addition, we have collected the following categories of sensitive personal information (as described in the CCPA) in the past 12 months:
- Personal information that reveals your precise geolocation.
For further details on the sensitive personal information we collect and how we obtain this information, please review the above section titled Information Collection.
We collect, use, and disclose this sensitive personal information as necessary to provide the Service or products as reasonably expected by an average consumer who accesses the Service or requests such products.
We do not use your sensitive personal information for purposes other than permissible business purposes under the CCPA. Additionally, we do not “sell” or “share” your sensitive personal information as those terms are defined by the CCPA.
Wizards retains each category of personal information, including sensitive personal information, for the length of time that is reasonably necessary for the purpose for which it was collected, and as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
D. Right to Know, Correct, and Delete
If you are a California resident, you have the right to know certain information about our data practices. In particular, you have the right to request the following from us:
- The categories of personal information we have collected about you;
- The categories of sources from which the personal information was collected;
- The categories of personal information about you that we disclosed for a business purpose or sold or shared;
- The categories of third parties to whom the personal information was disclosed for a business purpose or sold or shared; and
- The business or commercial purpose for collecting or selling or sharing your personal information.
You also have the right to request the specific pieces of personal information we have collected about you.
In addition, you have the right to correct or delete the personal information we have collected from you. These rights are subject to certain exceptions and also apply to sensitive personal information.
To exercise any of these rights, please submit a request through our online form available at https://support.wizards.com/ or call our toll-free number at (800) 324-6496. If you have an account with us, we may require you to use the account to submit the request. In the request, please specify which right you are seeking to exercise and the scope of the request. We will confirm receipt of your request within 10 business days and respond to your request within 45 days. We may require specific information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your requests to know, correct, or delete.
E. Right to Opt-Out of Sales and Sharing
To the extent Wizards sells or shares your personal information as the terms “sell” or “share” are defined under the California Consumer Privacy Act, you have the right to opt-out of the sale or sharing of your personal information by us to third parties at any time.
Wizards account holders, including Magic: The Gathering Arena users, may opt out by clicking here.
D&D Beyond account holders may opt out by clicking here.
Note that when you submit an opt-out, your opt-out will only apply to sales and shares of personal information through tracking technologies from the specific browser from which you submitted the opt-out because the connection between your browser identifiers and other personal information we have about you is not known to us. If you want the opt-out to also apply to other personal information we have about you (such as your contact information), please use the link and provide your contact information as requested or make sure you are logged into your account when submitting the opt-out. You may also submit a request to opt out by calling our toll-free number at (800) 324-6496 or emailing us at firstname.lastname@example.org.
F. Authorized Agent
You can designate an authorized agent to submit requests on your behalf. Requests must be submitted through the methods listed above. Except for opt-out requests, we will require written proof of the agent’s permission to do so and verify your identity directly.
G. Right to Non-Discrimination
You have the right not to receive discriminatory treatment by us for the exercise of any of your rights.
H. California Minors
We do not knowingly sell information of minors under 16 who are residents of California without their affirmative authorization, or the affirmative authorization of their parent or guardian for minors under 13. Affirmative authorization can be withdrawn at any time by emailing us at email@example.com or calling our toll-free number at (800) 324-6496. If you are a California resident under 18 years old and registered to use the Service, you can ask us to remove any content or information you have posted on the Service. To make a request, email us at firstname.lastname@example.org with “California Under 18 Content Removal Request” in the subject line, and tell us what you want removed. We will make reasonable good faith efforts to remove the post from prospective public view, although we cannot ensure the complete or comprehensive removal of the content and may retain the content as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
I. Shine the Light
Customers who are residents of California may request (1) a list of the categories of personal information disclosed by us to third parties during the immediately preceding calendar year for those third parties’ own direct marketing purposes; and (2) a list of the categories of third parties to whom we disclosed such information. To exercise a request, please write us at the email or postal address set out in the Contact Us section above and specify that you are making a “California Shine the Light” request. We may require additional information from you to allow us to verify your identity, and we are only required to respond to requests once during any calendar year.
15. Additional Disclosure for Nevada Residents
If you are a Nevada consumer, you have the right to direct us not to sell any covered information (as that term is defined by NRS 603A.340) that we have collected or will collect about you. A “sale” under Nevada law is the exchange of covered information for monetary consideration by a business to a third party for the third party to license or sell the covered information to other third parties. If you are a Nevada consumer and wish to exercise this right, please contact us as at https://support.wizards.com/.
16. ADDITIONAL DISCLOSURES FOR VIRGINIA RESIDENTS
Virginia provides additional rights to Virginia residents through the Virginia Consumer Data Protection Act (“VCDPA”). This section addresses those rights and applies only to Virginia residents. You have the following rights under the VCDPA:
- To confirm whether or not we are processing your personal data;
- To access your personal data;
- To correct inaccuracies in your personal data;
- To delete your personal data;
- To obtain a copy of your personal data that you previously provided to us in a portable and readily usable format; and
- To opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
To exercise any of these rights, please contact us through this Form. Wizards will respond to your request within 45 days. If you have an account with us, we may require you to use the account to submit the request. We may require specific information from you to help us verify your identity and process your request.
If we refuse to take action on a request, you may appeal our decision within a reasonable period of time by contacting us at email@example.com and specifying you wish to appeal. Within 60 days of our receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you may submit a complaint to the Virginia Attorney General at https://www.oag.state.va.us/consumercomplaintform.
17. ADDITIONAL DISCLOSURES FOR COLORADO RESIDENTS
Effective July 1, 2023, the Colorado Privacy Act (“CPA”) provides specific rights to Colorado residents. This section addresses those rights and applies only to Colorado residents.
If you are a Colorado resident, you have a right under the CPA to access all of the personal information we have collected from you and that we maintain about you, to obtain a portable copy of that information, and a right to request deletion or correction of that information.
Under the CPA, we must obtain your clear, affirmative consent for:
- Selling your personal data, as “selling” is defined in the CPA;
- Processing your personal data for targeted advertising using Matched Ads (defined in the Analytics and Advertising section above); and
- Processing any personal or sensitive information for any Child or Children living in Colorado.
You may additionally opt out of any sales or processing of any data for which we formerly obtained your consent.
Data Minimization: We must also limit the data we store by reviewing no less than annually whether storage of your information serves a legitimate business purpose and removing that data if no legitimate business purpose is identified.
Re-Obtaining Consent: We may re-seek consent from you if you have previously opted out from processing activities. If you have not interacted with us for at least one year, we are required by the CPA to re-obtain your affirmative consent to process any of your information.
For clarification on any of these rights and requirements or to submit a request for us to access, correct, or delete your information, please contact us through this Form. Wizards will respond to your request within 45 days. If you have an account with us, we may require you to use the account to submit the request. We may require specific information from you to help us verify your identity and process your request.
If we refuse to take action on a request, you may appeal our decision within a reasonable period of time by contacting us at firstname.lastname@example.org and specifying you wish to appeal. Within 60 days of our receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you may submit a complaint to the Colorado Attorney General at https://complaints.coag.gov/s/contact-us or by phone at (720) 508-6000.
18. ADDITIONAL DISCLOSURES FOR CONNECTICUT RESIDENTS
Effective July 1, 2023, the Connecticut Data Privacy Act (“CTDPA”) provides specific rights to Connecticut residents. This section addresses those rights and applies only to Connecticut residents.
Under the CTDPA, you have a right to access, correction, and deletion of your personal information. You further have the right to obtain from us a portable copy of your personal data to the extent it is technically feasible for us to provide such a copy.
You may also opt out of processing for:
- Targeted advertising (“Matched Ads” in Analytics and Advertising, above); and
- Sale of personal data, as “sale” is defined in the CTDPA.
Consent: We must obtain your direct, clear consent for processing of any sensitive personal information, and must provide an effective method to you for revocation of consent. If we receive a revocation request, we must cease processing your data within 15 days.
Children in Connecticut: We may not process children’s personal data for targeted advertising or sell children’s personal data. We must obtain consent to use personal data for targeted advertising or sell personal data from a person aged 13 to 15 when we have actual knowledge that that person is between 13 and 15.
For clarification on any of these rights and requirements or to submit a request for us to access, correct, or delete your information, please contact us through this Form. Wizards will respond to your request within 45 days. If you have an account with us, we may require you to use the account to submit the request. We may require specific information from you to help us verify your identity and process your request.
If we refuse to take action on a request, you may appeal our decision within a reasonable period of time by contacting us at email@example.com and specifying you wish to appeal. Within 60 days of our receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you may submit a complaint to the Connecticut Attorney General at https://www.dir.ct.gov/ag/complaint/ or (860) 808-5420.
19. ADDITIONAL DISCLOSURES FOR DATA SUBJECTS IN EUROPEAN ECONOMIC ZONE, SWITZERLAND, AND UNITED KINGDOM
The European Economic Area, Switzerland, and the United Kingdom (collectively, “Europe”) provide additional rights to individuals located in those jurisdictions, including through the General Data Protection Regulation (“GDPR”). This section addresses those rights and applies only to those individuals.
Data protection laws in Europe distinguish between organizations that process personal data for their own purposes (known as “controllers”) and organizations that process personal data on behalf of other organizations (known as “processors”). Wizards acts as a controller with respect to personal data collected as you interact with our websites, emails, and advertisements.
B. Lawful Basis for Processing
Data protection laws in Europe require a “lawful basis” for processing personal data. Our lawful bases include where: (1) you have given consent to the processing for one or more specific purposes, either to us or to our service providers or partners; (2) processing is necessary for the performance of a contract with you; (3) processing is necessary for compliance with a legal obligation; or (4) processing is necessary for the purposes of the legitimate interests pursued by us or a third party, and your interests and fundamental rights and freedoms do not override those interests.
C. Your European Privacy Rights
If you are a data subject in Europe, you have the right to access, rectify, or erase any personal data we have collected about you through the Service. You also have the right to data portability, right to be forgotten, and the right to restrict or object to our processing of personal data we have collected about you through the Service. In addition, you have the right to ask us not to process your personal data (or provide it to third parties to process) for marketing purposes or purposes materially different than for which it was originally collected or subsequently authorized by you. You may withdraw your consent at any time for any data processing we do based on consent you have provided to us.
To exercise any of these rights, please submit through this Form. We will respond to your request within 30 days. We may require additional information from you to allow us to confirm your identity. Please note that we store information as necessary to fulfil the purposes for which it was collected and may continue to retain and use the information even after a data subject request for purposes of our legitimate interests, including as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
If you have any issues with our compliance, you have the right to lodge a complaint with a European supervisory authority.
D. Children in Europe